CVE-2025-26899
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 15, 2025
CWE ID 352
Summary
CVE-2025-26899 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Recapture Cart Recovery and Email Marketing Recapture for WooCommerce. attackers can exploit this issue to trick users into performing unintended actions on their own site, such as changing orders or account information. This affects all versions of Recapture for WooCommerce from n/a through 1.0.43. It is essential for WooCommerce users to update to a patch version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.